Логотип exploitDog
bind:"GHSA-cwpg-qgc6-jxvq" OR bind:"CVE-2023-24531"
Консоль
Логотип exploitDog

exploitDog

bind:"GHSA-cwpg-qgc6-jxvq" OR bind:"CVE-2023-24531"

Количество 7

Количество 7

github логотип

GHSA-cwpg-qgc6-jxvq

около 1 года назад

Command go env is documented as outputting a shell script containing the Go environment. However, go env doesn't sanitize values, so executing its output as a shell script can cause various bad bahaviors, including executing arbitrary commands or inserting new environment variables. This issue is relatively minor because, in general, if an attacker can set arbitrary environment variables on a system, they have better attack vectors than making "go env" print them out.

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2023-24531

около 1 года назад

Command go env is documented as outputting a shell script containing the Go environment. However, go env doesn't sanitize values, so executing its output as a shell script can cause various bad bahaviors, including executing arbitrary commands or inserting new environment variables. This issue is relatively minor because, in general, if an attacker can set arbitrary environment variables on a system, they have better attack vectors than making "go env" print them out.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2023-24531

около 1 года назад

Command go env is documented as outputting a shell script containing the Go environment. However, go env doesn't sanitize values, so executing its output as a shell script can cause various bad bahaviors, including executing arbitrary commands or inserting new environment variables. This issue is relatively minor because, in general, if an attacker can set arbitrary environment variables on a system, they have better attack vectors than making "go env" print them out.

CVSS3: 9.8
EPSS: Низкий
msrc логотип

CVE-2023-24531

10 дней назад

Output of "go env" does not sanitize values in cmd/go

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2023-24531

около 1 года назад

Command go env is documented as outputting a shell script containing t ...

CVSS3: 9.8
EPSS: Низкий
redos логотип

ROS-20241015-09

11 месяцев назад

Уязвимость golang

CVSS3: 5.3
EPSS: Низкий
fstec логотип

BDU:2024-08391

около 2 лет назад

Уязвимость языка программирования Golang, связанная с непринятием мер по нейтрализации специальных элементов, позволяющая нарушителю выполнить произвольный код

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-cwpg-qgc6-jxvq

Command go env is documented as outputting a shell script containing the Go environment. However, go env doesn't sanitize values, so executing its output as a shell script can cause various bad bahaviors, including executing arbitrary commands or inserting new environment variables. This issue is relatively minor because, in general, if an attacker can set arbitrary environment variables on a system, they have better attack vectors than making "go env" print them out.

CVSS3: 9.8
0%
Низкий
около 1 года назад
ubuntu логотип
CVE-2023-24531

Command go env is documented as outputting a shell script containing the Go environment. However, go env doesn't sanitize values, so executing its output as a shell script can cause various bad bahaviors, including executing arbitrary commands or inserting new environment variables. This issue is relatively minor because, in general, if an attacker can set arbitrary environment variables on a system, they have better attack vectors than making "go env" print them out.

CVSS3: 9.8
0%
Низкий
около 1 года назад
nvd логотип
CVE-2023-24531

Command go env is documented as outputting a shell script containing the Go environment. However, go env doesn't sanitize values, so executing its output as a shell script can cause various bad bahaviors, including executing arbitrary commands or inserting new environment variables. This issue is relatively minor because, in general, if an attacker can set arbitrary environment variables on a system, they have better attack vectors than making "go env" print them out.

CVSS3: 9.8
0%
Низкий
около 1 года назад
msrc логотип
CVE-2023-24531

Output of "go env" does not sanitize values in cmd/go

CVSS3: 9.8
0%
Низкий
10 дней назад
debian логотип
CVE-2023-24531

Command go env is documented as outputting a shell script containing t ...

CVSS3: 9.8
0%
Низкий
около 1 года назад
redos логотип
ROS-20241015-09

Уязвимость golang

CVSS3: 5.3
0%
Низкий
11 месяцев назад
fstec логотип
BDU:2024-08391

Уязвимость языка программирования Golang, связанная с непринятием мер по нейтрализации специальных элементов, позволяющая нарушителю выполнить произвольный код

CVSS3: 9.8
0%
Низкий
около 2 лет назад

Уязвимостей на страницу